CVE-2012-0806: Buffer Overflow
Published Jan 27, 2012
·Updated
Buffer overflow in Bip 0.8.8 and earlier might allow remote authenticated users to execute arbitrary code via vectors involving a series of TCP connections that triggers use of many open file descriptors.
Affected Software
17 affected components
Duckcorp Bip<=0.8.8
Duckcorp Bip=0.7.0
Duckcorp Bip=0.7.1
Duckcorp Bip=0.7.2
Duckcorp Bip=0.7.3
Duckcorp Bip=0.7.4
Duckcorp Bip=0.7.5
Duckcorp Bip=0.8.0
Duckcorp Bip=0.8.0-rc0
Duckcorp Bip=0.8.0-rc1
Duckcorp Bip=0.8.1
Duckcorp Bip=0.8.2
Duckcorp Bip=0.8.3
Duckcorp Bip=0.8.4
Duckcorp Bip=0.8.5
Duckcorp Bip=0.8.6
Duckcorp Bip=0.8.7
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jan 27, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0806?
CVE-2012-0806 has a moderate severity rating due to its potential to allow remote authenticated users to execute arbitrary code.
2
How do I fix CVE-2012-0806?
To fix CVE-2012-0806, upgrade to Bip version 0.8.9 or later, as earlier versions are vulnerable.
3
What causes CVE-2012-0806?
CVE-2012-0806 is caused by a buffer overflow vulnerability when handling multiple TCP connections.
4
Who is affected by CVE-2012-0806?
CVE-2012-0806 affects users of Bip versions up to and including 0.8.8 and earlier.
5
What is the potential impact of CVE-2012-0806?
The potential impact of CVE-2012-0806 includes arbitrary code execution leading to system compromise.